Rogue Access Point Detection

The process flow of a rogue AP being detected in a WLAN environment is based on the LWAPs already being powered up and associated to their controllers. The WLC detects a rogue AP and immediately notifies WCS, which creates a rogue AP alarm that appears in the lower-left corner of the user interface pages. Simply selecting the indicator displays the Rogue AP Alarms page.

Rogue Access Point Alarms

The alarms for rogue APs are naturally listed on the Rogue Access Point Alarms page. This page details the severity, the rogue MAC address, the vendor, the radio type, the strongest AP RSSI, the date and time, the channel number, and the SSID. You can view further details by clicking the link in the Rogue MAC Address column. Then you see the associated Alarms > Rogue AP MAC Address page. To view rogue AP information using the menu bar, choose Monitor > Alarms > Rogue AP Alarms.

You can handle the alarms by checking a box to the left of the severity and manage them using the Select a Command drop-down menu. The choices available are Assign to Me, Unassign, Delete, Clear, or Email Notification.

Rogue Access Point Location

To see the rogue AP calculated location on a map, choose Map from the Rogue AP MAC Address page, or from the menu bar choose Monitor > Maps > Building Name > Floor Name. A small skull-and-crossbones indicator appears at the calculated location. The calculated location is to the nearest AP based on the strongest RSSI with WCS Base. WCS Location compares the RSSI signal strength from multiple APs to pinpoint the most probable location using RF fingerprinting technology.

Foundation Summary

The "Foundation Summary" is a collection of information that provides a convenient review of many key concepts in this chapter. If you are already comfortable with the topics in this chapter, this summary can help you recall a few details. If you just read this chapter, this review should help solidify some key facts. If you are doing your final preparation before the exam, the information in this section is a convenient way to review the day before the exam.

Following are the five elements of Cisco Unified Wireless Network:

■ Client devices—Use the Cisco Compatible Extensions program helps ensure interoperability. The Cisco Compatible Extensions program delivers services such as wireless mobility, QoS, network management, and enhanced security.

■ Mobility platform—Provides ubiquitous access in any environment indoors or out. The lightweight access points (LWAP) are dynamically configured and managed by wireless LAN controllers (WLC) through LightWeight Access Point Protocol (LWAPP).

■ Network unification—Creates seamless integration into the routing and switching infrastructure. The WLCs are responsible for functions such as RF management, n+1 deployment, and Intrusion Prevention System (IPS).

■ World-class network management—Enables wireless local-area network (WLANs) to have the equivalent LAN security, scalability, reliability, ease of deployment, and management via Cisco Wireless Control System (WCS). Cisco WCS provides features for design, control, and monitoring.

■ Unified advanced services—Support new mobility applications, emerging Wi-Fi technologies, and advanced threat detection and prevention capabilities such as wireless VoIP, future unified cellular, location services, Network Admission Control (NAC), the Self-Defending Network, (Identity Based Network Services(IBNS), Intrusion Detection Systems (IDS), and guest access.

Cisco offers two WLAN implementations: autonomous and lightweight. Table 10-5 contrasts the two solutions.

Table 10-5 Comparison of WLAN Implementation Solutions

Category

Autonomous WLAN Solution

Lightweight WLAN Solution

Access Point

Autonomous APs

LWAPs

Control

Individual configuration on each AP

Configuration via Cisco WLC

Table 10-5 Comparison of WLAN Implementation Solutions (Continued)

Category

Autonomous WLAN Solution

Lightweight WLAN Solution

Dependency

lndependent operation

Dependent on Cisco WLC

WLAN Management

Management via CiscoWorks WLSE and Wireless Domain Services (WDS)

Management via Cisco WCS

Redundancy

AP redundancy

Cisco WLC redundancy

CiscoWorks WLSE is a management tool for WLANs with autonomous APs. It is designed to centralize management, reduce total cost of ownership, minimize security vulnerabilities, and improve WLAN uptime. Features and benefits of Cisco WLSE are summarized in Table 10-6.

Table 10-6 CiscoWorks WLSE Features and Benefits

Readers' Questions

  • ky
    How to prevent rogue access points?
    3 months ago
  • William Fowler
    Which device can control and manage a large number of corporate aps?
    10 months ago
  • A network appliance or enterprise server.

    Feature

    Benefit

    Centralized configuration, firmware, and radio management

    Reduces WLAN total cost of ownership by saving time and resources required to manage large numbers of APs

    Autoconfiguration of new APs

    Simplifies large-scale deployments

    Security policy misconfiguration alerts and rogue AP detection

    Minimizes security vulnerabilities

    AP utilization and client association reports

    Helps in capacity planning and troubleshooting

    Proactive monitoring of APs, bridges, and 802.1x EAP1 servers

    Improves WLAN uptime

    1 EAP = extensible authentication protocol

    CiscoWorks WLSE supports Secure Shell (SSH), HTTP, Cisco Discovery Protocol (CDP), and Simple Network Management Protocol (SNMP). CiscoWorks WLSE comes in two versions: CiscoWorks WLSE and WLSE Express. CiscoWorks WLSE supports up to 2500 WLAN devices. WLSE Express supports up to 100 WLAN devices. The WLSE Express setup option is either Automatic or Manual.

    Cisco WCS is a Cisco WLAN solution network-management tool that is designed to support 50 Cisco WLCs and 1500 APs. Cisco WCS supports SNMPvl, SNMPv2, and SNMPv3.

    Cisco WCS comes in three versions:

    ■ Cisco WCS Base—The base version of Cisco WCS can determine which AP a wireless device is associated with.

    ■ Cisco WCS Location—Cisco WCS Location is the base plus Cisco RF fingerprinting technology.

    ■ Cisco WCS Location + 2700 Series Wireless Location Appliance—Cisco Wireless Location + 2700 Appliance tracks thousands of devices in real time, enabling key business applications such as asset tracking, inventory management, and e911.

    The Cisco Wireless Location Appliance provides simultaneous device tracking and data collection for capacity management or location trending:

    ■ The Cisco Wireless Location Appliance is an innovative, easy-to-deploy solution that uses advanced RF fingerprinting technology to simultaneously track thousands of 802.11 wireless devices from directly within a WLAN infrastructure.

    ■ Cisco 2700 Series Wireless Location Appliances are servers that enhance the high-accuracy built-in Cisco WCS location abilities by computing, collecting, and storing historical location data for up to 1500 laptop clients, palmtop clients, Voice over IP (VoIP) telephone clients, radio frequency identification (RFID) asset tags, rogue APs, and rogue AP clients.

    To access the Cisco WCS Network Summary page, choose Monitor > Network Summary.

    To access the Cisco WCS Controller Summary details, choose Monitor > Devices > Controllers.

    The default Cisco WCS username is root, and the default password is public.

    The WLC detects rogue APs and immediately notifies the WCS, which in turn creates a rogue AP alarm in the lower-left corner of the user interface pages. To view rogue AP information using the menu bar, choose Monitor > Alarms > Rogue AP Alarms. The alarms choices available are Assign to Me, Unassign, Delete, Clear, or Email Notification. To see the location of a rogue AP, either choose Map from the Rogue AP MAC Address page, or choose Monitor > Maps > Building Name > Floor Name from the menu bar. A small skull-and-crossbones indicator appears at the calculated location.

    Q&A

    Some of the questions that follow challenge you more than the exam by using an open-ended question format. By reviewing now with this more difficult question format, you can exercise your memory better and prove your conceptual and factual knowledge of this chapter. The answers to these questions appear in Appendix A.

    1. Discuss the different characteristics and advantages of the two WLAN solutions.

    2. Does WLSE support both lightweight and autonomous access points?

    3. When do you use CiscoWorks WLSE versus WLSE Express?

    4. Discuss the platform support for Cisco WCS.

    5. What are the three WCS versions for tracking wireless devices?

    6. When does Cisco WCS listen for rogue access points?

    7. How do you add lightweight access points to the WCS database?

    8. Does Cisco WCS support SNMPv3?

    9. What page is displayed upon a successful WCS login?

    10. What is the Cisco WCS default username and password?

    11. For the WLAN components, what are the WLAN Management solutions?

    12. What happens to Rogue APs when they are detected?

    13. What are the differences between WCS base, Location, and Location + Appliance (including how many clients can be tracked)?

    Was this article helpful?

    0 0